Attackers have exploited fake GitHub accounts to claim a $5,000 CLAW token airdrop, directing users to a cloned site mimicking openclaw ai. The site uses hidden "connect wallet" prompts and heavily obfuscated JavaScript to steal funds. Many of these accounts were deleted within hours of creation. No victims have been confirmed yet. Security agencies advise blocking malicious domains and avoiding connecting wallets to unknown sites. Users who have already connected are urged to revoke permissions immediately.